Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Security Onion - Scaling SIEM for Enterprise Environments

Hack In The Box Security Conference via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore advanced enterprise-scale deployment strategies for Security Onion, the open-source SIEM solution, through a comprehensive 59-minute conference presentation from cybersecurity specialists Piroon Srisawang, Peerapong Thongpubet, and Korrawit Chaikangwan. Learn how to overcome Security Onion's default architectural limitations in demanding enterprise environments through practical case studies and custom component development. Discover solutions for implementing robust multi-team tenancy, scalable detection rule management, and granular access control mechanisms. Master the engineering of externalized login portals with enterprise identity provider integration including LDAP and SAML-based SSO solutions. Understand sophisticated access gateway development for role-based access control and logical data separation across security teams. Examine centralized detection rule lifecycle management platforms enabling version control, automated deployment, and standardized distribution of Suricata, Zeek, and Wazuh rules across multiple Security Onion nodes. Investigate high-volume log ingestion techniques achieving 100,000 Events Per Second using kernel bypass technology and DPDK for real-time comprehensive data analytics. Address ongoing challenges including threat intelligence integration limitations with STIX/TAXII standards and core system version compatibility issues. Gain invaluable insights into adapting open-source SIEM solutions for production-grade enterprise deployment, including critical architectural considerations, trade-offs, and practical lessons from augmenting community-driven security tools for demanding operational environments.

Syllabus

#OOTB2025BKK - Security Onion: Scaling SIEM - P. Srisawang, P. Thongpubet & K. Chaikangwan

Taught by

Hack In The Box Security Conference

Reviews

Start your review of Security Onion - Scaling SIEM for Enterprise Environments

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.